Cybersecurity terminology · MLC-0102
Cybersecurity terms: T (238)
- T1. The MAC.
- (t + k)-way combination coverageFor a given test set that provides 100% t-way coverage for n variables, (t+k)-way combination coverage is the...
- T192(X)A truncation function that outputs the most significant (i.e., leftmost) 192 bits of the input bit string X.
- [T]_21. A binary representation for the integer T (using an agreed-upon length and bit order).
- TA1. Entity authorized to act as a representative of an Agency in confirming Subscriber identification during...
- Tabletop ExerciseA discussion-based exercise where personnel with roles and responsibilities in a particular IT plan meet in a...
- tabletop materialsMaterials designed for a discussion-based exercise in which personnel with roles and responsibilities in a...
- Tactic Technique Procedure, see TTP
- tactical cross domain solution (CDS)A CDS that operates in austere environment conditions or environments where terrestrial communications are...
- tactical dataInformation that requires protection from disclosure and modification for a limited duration as determined by...
- tactical edgeThe platforms, sites, and personnel (U. S. military, allied, coalition partners, first responders) operating...
- Tag1. A cryptographic checksum on data that is designed to reveal both accidental errors and the intentional...
- Tag Talks FirstAn RF transaction in which the tag communicates its presence to a reader. The reader may then send commands...
- tailored control baseline1. A set of controls resulting from the application of tailoring guidance to a control baseline. See...
- Tailored Security Control Baseline1. A set of security controls resulting from the application of tailoring guidance to the security control...
- tailoring1. The process by which security control baselines are modified by identifying and designating common...
- tailoring assessment proceduresThe process by which assessment procedures defined in SP 800-53A are adjusted or scoped to match the...
- taintingThe process of embedding covert capabilities in information, systems, or system components to allow...
- Tamper evidentA process which makes alterations to the data easily detectable.
- Tamper resistantA process which makes alterations to the data difficult (hard to perform), costly (expensive to perform), or...
- tamperingAn intentional but unauthorized act resulting in the modification of a system, components of systems, its...
- TargetThe set of specific IT systems or applications for which a checklist has been created.
- Target Identification and Analysis TechniquesInformation security testing techniques, mostly active and generally conducted using automated tools, that...
- Target NameA single WFN that is the target of a matching process. A matching engine compares a source WFN to a target...
- target of evaluation (TOE)1. In accordance with Common Criteria, an information system, part of a system or product, and all associated...
- Target Operational EnvironmentThe IT product’s operational environment, such as Standalone, Managed, or Custom (with description, such as...
- Target PlatformThe target operating system or application on which a vendor product will be evaluated using a...
- Target Profile1. the desired outcome or ‘to be’ state of cybersecurity implementation
- Target Residual RiskThe amount of risk that an entity prefers to assume in the pursuit of its strategy and business objectives...
- Target ValueA single value that is the target of a matching process. A matching engine compares a source value to a...
- Target Vulnerability Validation TechniquesActive information security testing techniques that corroborate the existence of vulnerabilities. They...
- targeted poisoning attackA poisoning attack that changes the prediction on a small number of targeted samples.
- Targeted security strength1. The security strength that is intended to be supported by one or more implementation-related choices (such...
- task1. An activity that is directed toward the achievement of organizational objectives.
- TaxonomyA scheme of classification.
- TCBTotality of protection mechanisms within a computer system, including hardware, firmware, and software, the...
- TCBCTDEA Cipher Block Chaining Mode of Operation
- TCBC-ITDEA Cipher Block Chaining Mode of Operation - Interleaved
- TCFBTDEA Cipher Feedback Mode of Operation
- TCFB-PTEA Cipher Feedback Mode of Operation - Pipelined
- TCP1. TCP is one of the main protocols in TCP/IP networks. Whereas the IP protocol deals only with packets, TCP...
- TDEA1. An approved cryptographic algorithm that specifies both the DEA cryptographic engine employed by TDEA and...
- TDESTriple Data Encryption Standard specified in FIPS 46-3
- TEAn event or situation that has the potential for causing undesirable consequences or impact.
- TeamA number of persons associated together in work or activity. As used in this publication, a team is a group...
- tebibyte2^(40) bytes.
- TECBTDEA Electronic Codebook Mode of Operation
- technical community (TC)Government/Industry/Academia partnerships formed around major technology areas to act like a standards body...
- technical controls1. The security controls (i.e., safeguards or countermeasures) for an information system that are primarily...
- technical profileA fully conformant subset of functionality of a protocol or standard. Technical profiles are used to enhance...
- technical reference model (TRM)A component-driven, technical framework that categorizes the standards and technologies to support and enable...
- technical riskThe risk associated with the evolution of the design and the production of the system of interest affecting...
- technical safeguardsThe technology and the policy and procedures for its use that protect electronic protected health information...
- technical security materialEquipment, components, devices, and associated documentation or other media which pertain to cryptography, or...
- technical surveillance countermeasures (TSCM)Techniques to detect, neutralize, and exploit technical surveillance technologies and hazards that permit the...
- technical vulnerability information1. A hardware, firmware, communication, or software flaw that leaves a computer processing system open for...
- technique1. A set or class of technologies and processes intented to acheive one or more objectives by providing...
- Technology-Based Input ProductManufactured components used in the organization manufacturing process incorporating information technology...
- TEEAn area or enclave protected by a system processor.
- TEK, see traffic encryption key (TEK)
- telecommunications1. The term 'telecommunications' means the transmission, between or among points specified by the user, of...
- telecommunications security (TSEC) nomenclature1. The National Security Agency (NSA) system for identifying the type and purpose of certain items of COMSEC...
- telemetryThe science of measuring a quantity or quantities, transmitting the results to a distant station, and...
- TEMPESTA name referring to the investigation, study, and control of unintentional compromising emanations from...
- TEMPEST Advisory Group, see Tag
- TEMPEST certified equipment or systemEquipment or systems that have been certified to meet the applicable level of NSTISSAM TEMPEST/1-92 or...
- TEMPEST zoneDesignated area within a facility where equipment with appropriate TEMPEST characteristics (TEMPEST zone...
- Template Attack, see TA
- Template GeneratorIn the PIV context a template generator is a software library providing facilities for the conversion of...
- Template MatcherIn the PIV context a matcher is a software library providing for the comparison of images conformant to...
- Temporal metricsdescribe the characteristics of misuse vulnerabilities that can change over time but remain constant across...
- Tennessee Eastman, see TE
- Term of SupportThe length of time for which the device will be supported by the manufacturer or supporting parties for such...
- Test1. A type of assessment method that is characterized by the process of exercising one or more assessment...
- test actionThe action to be performed based on the response to a particular question. Examples of test actions are...
- Test DirectorA person responsible for all aspects of a test, including staffing, development, conduct, and logistics.
- Test Evidence, see TE
- Test GuideA document that outlines the basic steps involved in conducting a test and includes a list of the...
- test keyKey intended for testing of COMSEC equipment or systems. If intended for off-the-air, in-shop use, such key...
- Test PlanA document that outlines the specific steps that will be performed for a particular test, including the...
- Test Toolsare a means of testing to confirm that an IT product, process, or service conforms to the requirements of a...
- Test, Training, and Exercise (TT&E) EventAn event used to support the maintenance of an IT plan by allowing organizations to identify problems related...
- Test, Training, and Exercise (TT&E) PlanA plan that outlines the steps to be taken to ensure that personnel are trained in their IT plan roles and...
- Test, Training, and Exercise (TT&E) PolicyA policy that outlines an organization’s internal and external requirements associated with training...
- Test, Training, and Exercise (TT&E) ProgramA means for ensuring that personnel are trained in their IT plan roles and responsibilities; IT plans are...
- Test, Training, and Exercise (TT&E) Program CoordinatorA person who is responsible for developing a TT&E plan and coordinating TT&E events.
- TestingDetermination of one or more characteristics of an object of conformity assessment, according to a procedure.
- testing data controlA capability with which an attacker controls the testing data input to the machine learning model.
- Testing laboratoryAn accredited cryptographic security testing laboratory.
- TestResultThe container for XCCDF results. May be the root node of an XCCDF results document.
- TEXTnBlock of data representing Plaintext n, if encryption state, or Ciphertext n,
- TFS, see traffic flow security (TFS)
- Third-party ProvidersService providers, integrators, vendors, telecommunications, and infrastructure support that are external to...
- Third-Party Relationships1. relationships with external entities. External entities may include, for example, service providers...
- Third-party testingIndependent testing by an organization that was not involved in the design and implementation of the object...
- ThreadA defined group of instructions executing apart from other similarly defined groups, but sharing memory and...
- threat1. Any circumstance or event with the potential to adversely impact organizational operations (including...
- threat actor1. An individual or a group posing a threat.
- threat analysis1. Formal description and evaluation of threat to a system or organization.
- Threat Assessment/Analysis1. Formal description and evaluation of threat to a system or organization.
- threat eventAn event or situation that has the potential for causing undesirable consequences or impact.
- threat event outcomeThe effect a threat acting upon a vulnerability has on the confidentiality, integrity, and/or availability of...
- threat information1. Analytical insights into trends, technologies, or tactics of an adversarial nature affecting information...
- threat intelligenceThreat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the...
- Threat Intelligence ReportA prose document that describes TTPs, actors, types of systems and information being targeted, and other...
- threat modelingA form of risk assessment that models aspects of the attack and defense sides of a logical entity, such as a...
- threat monitoringAnalysis, assessment, and review of audit trails and other information collected for the purpose of searching...
- threat scenario1. A set of discrete threat events, associated with a specific threat source or multiple threat sources...
- Threat Shifting1. The response of actors to perceived safeguards and/or countermeasures (i.e., security controls), in which...
- Threat Signaling1. Real-time signaling of DDoS-related telemetry and threat-handling requests and data between elements...
- threat source1. The intent and method targeted at the intentional exploitation of a vulnerability or a situation and...
- Three-key Triple Data Encryption AlgorithmThree-key Triple Data Encryption Algorithm specified in [NIST SP 800-67].
- threshold ruleUsually, with the threshold rule, a cell in a table of frequencies is defined to be sensitive if the number...
- ThresholdsValues used to establish concrete decision points and operational control limits to trigger management action...
- TiB2^(40) bytes.
- Tier 0 (central facility) (COMSEC)The composite facility approved, managed, and operated under National Security Agency (NSA) oversight that...
- Tier 1/common tier 1 (CT1) (COMSEC)The composite of the electronic key management system (EKMS) Common Tier 1 (CT1) systems that is a tool used...
- Tier 2 (COMSEC)The layer of the electronic key management system (EKMS) comprising COMSEC accounts and subaccounts managing...
- Tier 3 (COMSEC)The lowest tier or layer of electronic key management system (EKMS) architecture comprising hand-receipt...
- Tier I ChecklistA checklist in the National Checklist Repository that is prose-based, such as narrative descriptions of how a...
- Tier II ChecklistA checklist in the National Checklist Repository that documents the recommended security settings in a...
- Tier III ChecklistA checklist in the National Checklist Repository that uses SCAP to document the recommended security settings...
- Tier IV ChecklistA checklist in the National Checklist Repository that is considered production-ready and has been validated...
- tiered labelIndicates the degree to which a product has satisfied a specific standard, sometimes based on attaining...
- time bombResident computer program that triggers an unauthorized act at a predefined time.
- time intervalThe elapsed time between two events. In time and frequency metrology, time interval is usually measured in...
- time scaleAn agreed upon system for keeping time. All time scales use a frequency source to define the length of the...
- time series analysisThe analysis of an ordered sequence of values of a variable at equally spaced time intervals.
- time-compliance dateDate by which a mandatory modification to a COMSEC end-item must be incorporated if the item is to remain...
- time-dependent passwordPassword that is valid only at a certain time of day or during a specified interval of time.
- timestamp1. Contains the time and, possibly, other information; a component of timestamped_data.
- Timestamp PacketA unit of information that is transmitted by a TTA that contains timestamped_data and a timestamp_signature.
- timestamped_dataThe data on which a digital signature is generated by a TTA.
- timestamp_signatureTTAA digital signature that is generated using a TTA’s private signature key.
- timestamp_timeThe time provided in a timestamp.
- TjThe jth counter block.
- TlenThe bit length of the MAC.
- TLSAn authentication and encryption protocol widely implemented in browsers and Web servers. HTTP traffic...
- TMacTagBits(X)1. A truncation function that outputs the most significant (i.e., leftmost) MacTagBits bits of the input...
- TMOVSTDEA Modes of Operation Validation System
- TOE, see target of evaluation (TOE)
- TOFBTDEA Output Feedback Mode of Operation
- TOFB-ITDEA Output Feedback Mode of Operation - Interleaved
- token1. Something the cardholder possesses and controls (e.g., PIV Card or derived PIV credential) that is used to...
- Token Factory ContractA smart contract that defines and issues a token.
- Tool ConfigurationA recommendation for setting up and using tools that support the automated collection, exchange, processing...
- TOS, see trusted operating system
- Total Riskthe potential for the occurrence of an adverse event if no mitigating action istaken (i.e., the potential for...
- TPC, see two-person control
- TPI, see two-person integrity
- TPM, see Trusted Platform Module (TPM)
- TPPThe Venafi Machine Identity Protection platform used in the example implementation described in this practice...
- traceabilityDiscernible association among two or more logical entities, such as requirements, system elements...
- traceability matrix1. A matrix that records the relationship between two or more products of the development process (e.g., a...
- traceability, metrologicalProperty of a measurement result whereby the result can be related to a reference through a documented...
- TraceableInformation that is sufficient to make a determination about a specific aspect of an individual's activities...
- trade-offDecision-making actions that select from various requirements and alternative solutions on the basis of net...
- trade-off analysisDetermining the effect of decreasing one or more key factors and simultaneously increasing one or more other...
- traditional keyTerm used to reference symmetric key wherein both ends of a link or all parties in a cryptonet have the same...
- traffic encryption key (TEK)Key used to encrypt plain text or to superencrypt previously encrypted text and/or to decrypt cipher text.
- Traffic FilterAn entry in an access control list that is installed on the router or switch to enforce access controls on...
- Traffic Flow Confidentiality (TFC) PaddingDummy data added to real data in order to obfuscate the length and frequency of information sent over IPsec.
- traffic flow security (TFS)Techniques to counter traffic analysis.
- traffic paddingCountermeasure that generates spurious data in transmission media to make traffic analysis or decryption more...
- Training1. Instruction or learning activity to enhance the employee’s capacity to perform specific job functions and...
- training data controlA capability in which an attacker controls some or all of the training data of a machine learning model.
- training data extractionThe ability of an attacker to extract the training data of a generative model by prompting the model with...
- training keyKey intended for use for over-the-air or off-the-air training.
- training stageThe stage of a machine learning pipeline in which a model learns parameters that minimize its error against...
- tranquilityProperty whereby the security level of an object cannot change while the object is being processed by an...
- Transaction1. A discrete digital event between a user and a system that supports a business or programmatic purpose.
- Transaction feeAn amount of cryptocurrency charged to process a blockchain transaction. Given to publishing nodes to include...
- transdisciplinaryCreating a unity of intellectual frameworks beyond the disciplinary perspectives.
- Transducer CapabilitiesCapabilities that provide the ability for computing devices to interact directly with physical entities of...
- TRANSEC, see transmission security
- transfer cross domain solutionA type of cross domain solution (CDS) that enforces security policy for the movement of data between...
- transfer key encryption key (TrKEK)A key used to move key from a Key Processor to a data transfer device (DTD)/secure DTD2000 system...
- transfer of accountabilityThe process of transferring accountability for COMSEC material from the COMSEC account of the shipping...
- transformationThe conversion of one state or format into another state or format.
- Transforming ApplicationAn application that transforms a CBEFF Basic Data Structure from one Patron Format into another Patron...
- transmissionThe state that exists when information is being electronically sent from one location to one or more other...
- Transmission Control ProtocolTCP is one of the main protocols in TCP/IP networks. Whereas the IP protocol deals only with packets, TCP...
- transmission securityMeasures (security controls) applied to transmissions in order to prevent interception, disruption of...
- Transmitter Address, see TA
- transparency1. Amount of information that can be gathered about a supplier, product, or service and how far through the...
- Transponder1. An electronic device that communicates with RFID readers. A tag can function as a beacon or it can be used...
- Transport Control Protocol, see TCP
- Transport LayerLayer of the TCP/IP protocol stack that is responsible for reliable connection-oriented or connectionless...
- Transport Layer Security (TLS)1. An authentication and security protocol that is widely implemented in browsers and web servers. TLS...
- Transport Mode1. IPsec mode that does not create a new IP header for each protected packet.
- trap door1. A means of reading cryptographically protected information by the use of private knowledge of weaknesses...
- trigger1. A set of logic statements to be applied to a data stream that produces an alert when an anomalous incident...
- Triple Data Encryption Algorithm1. An approved cryptographic algorithm that specifies both the DEA cryptographic engine employed by TDEA and...
- Triple Data Encryption Standard1. An implementation of the data encryption standard (DES) algorithm that uses three passes of the DES...
- Tripwire Enterprise, see TE
- TrKEK, see transfer key encryption key (TrKEK)
- TRM, see technical reference model (TRM)
- trojanIn the machine learning context, a malicious modification to a model that is difficult to detect, may appear...
- Trojan horse1. A computer program that appears to have a useful function, but also has a hidden and potentially malicious...
- truncationA process that shortens an input bitstring, preserving only a sub-string of a specified length.
- trust1. A belief that an entity meets certain expectations and therefore, can be relied upon.
- Trust Agent, see TA
- trust agreementA set of conditions under which a CSP, IdP, and RP are allowed to participate in a federation transaction to...
- trust anchor1. A public or symmetric key that is trusted because it is built directly into hardware or software or...
- trust assumptionAn assumption that characterizes how one expects a specific party to behave when given access to sensitive...
- Trust FrameworkThe “rules” underpinning federated identity management, typically consisting of: system, legal, conformance...
- Trust Framework Operators1. The entity responsible for the governance and administration of an identity federation.
- Trust Framework Providers1. The entity responsible for the governance and administration of an identity federation.
- Trust Management1. An ISCM capability that ensures that untrustworthy persons are prevented from being trusted with network...
- trust modelA collection of assumptions that characterize the trustworthiness of each component in a system.
- Trust Protection PlatformThe Venafi Machine Identity Protection platform used in the example implementation described in this practice...
- trust relationship1. An agreed upon relationship between two or more system elements that is governed by criteria for secure...
- TrustedAn element that another element relies upon to fulfill critical requirements on its behalf.
- trusted agent (TA)An individual explicitly aligned with one or more registration authority (RA) officers who has been delegated...
- Trusted Application, see TA
- Trusted associationAssurance of the integrity of an asserted relationship between items of information that may be provided by...
- Trusted bootA system boot where aspects of the hardware and firmware are measured and compared against known good values...
- trusted channel1. A channel where the endpoints are known and data integrity is protected in transit. Depending on the...
- Trusted compute poolA physical or logical grouping of computing hardware in a data center that is tagged with specific and...
- trusted computer systemA system that has the necessary security functions and assurance that the security policy will be enforced...
- trusted computing base (TCB)Totality of protection mechanisms within a computer system, including hardware, firmware, and software, the...
- trusted data recipientan entity that has limited access to the data that it receives as a result of being bound by some...
- Trusted Execution EnvironmentAn area or enclave protected by a system processor.
- trusted foundryFacility that produces integrated circuits with a higher level of integrity assurance. Note: Defense...
- trusted network-layer onboardingA network-layer onboarding process that: provides each device with unique network credentials, provides the...
- trusted operating system1. An operating system in which there exists a level of confidence (based on rigorous analysis and testing)...
- Trusted Party1. A party that can be expected to keep sensitive data safe and not disclose it to others.
- trusted path1. A mechanism by which a user (through an input device) can communicate directly with the security functions...
- Trusted Platform Module (TPM)A tamper-resistant integrated circuit built into some computer motherboards that can perform cryptographic...
- trusted poolA physical or logical grouping of computing hardware in a data center that is tagged with specific and...
- trusted processProcess that has been tested and verified to operate only as intended or expected by the user.
- trusted recoveryAbility to ensure recovery without compromise after a system failure.
- trusted refereeAn agent of the CSP who is trained to make risk-based decisions regarding an applicant’s identity proofing...
- Trusted Third Party1. An entity other than the owner and verifier that is trusted by the owner, the verifier or both to provide...
- Trusted Timestamp Authority (TTA)An entity that is trusted to provide accurate time information.
- trustworthiness1. The interdependent combination of attributes of a person, system, or enterprise that provides confidence...
- trustworthiness (system)1. The degree to which an information system (including the information technology components that are used...
- trustworthy information systemAn information system that is believed to be capable of operating within defined levels of risk despite the...
- TSCM, see technical surveillance countermeasures (TSCM)
- TSP, see Timestamp Packet
- TTAAn entity that is trusted to provide accurate time information.
- TTA_supplied_infoAdditional information that is included in the timestamped_data by a TTA during the generation of a...
- TTFAn RF transaction in which the tag communicates its presence to a reader. The reader may then send commands...
- TTP1. An entity other than the owner and verifier that is trusted by the owner, the verifier or both to provide...
- TTXA discussion-based exercise where personnel with roles and responsibilities in a particular IT plan meet in a...
- Tunnel Mode1. IPsec mode that creates a new IP header for each protected packet.
- Tunnel VPNAn SSL connection that allows a remote user to securely access a wide variety of protocols and applications...
- tunnelingEncapsulation of one protocol's packet within the payload of another protocol's packets. Note: Tunneling...
- Tuple DensitySum of t and the fraction of the covered (t+1)-tuples out of all possible (t+1)-tuples.
- Turing completeA system (computer system, programming language, etc.) that can be used for any algorithm, regardless of...
- TW-1(C)The output of the unwrapping function for TKW applied to the string C.
- Two-Factor AuthenticationProof of the possession of a physical or software token in combination with some memorized secret knowledge.
- Two-key Triple Data Encryption AlgorithmTwo-key Triple Data Encryption Algorithm specified in [NIST SP 800-67].
- two-person controlThe continuous surveillance and control of material at all times by a minimum of two authorized individuals...
- two-person integrity1. The system of storage and handling designed to prohibit individual access to certain COMSEC keying...
- TW(S)The output of the wrapping function for TKW applied to the string S.
- T(x, l)Truncation of the bit string x to the leftmost l bits of x, where l ≤ the length of x in bits
- type accreditationA form of accreditation that is used to authorize multiple instances of a major application or general...
- type certificationThe certification acceptance of replica information systems based on the comprehensive evaluation of the...
- Type I errorIncorrectly rejection of a true null hypothesis.
238 of 4,693 terms in Cybersecurity terminology (MLC-0102). Request the full dataset.